The noreply_google_com Leak Gave Attackers Everything for 40 Accounts
The noreply_google_com Combolist: A Small File Tied to Google-Related Logins
In June 2026, HEROIC analysts identified a small combolist labeled noreply_google_com being shared by a Telegram user. The file contains 40 records pairing email addresses with plaintext passwords and the URLs those credentials were used on.
Why Even 40 Records Deserve Attention
This is one of the smallest files HEROIC has tracked recently, but each of the 40 records still gives an attacker a working email and password pair. For the people behind those 40 accounts, the risk is exactly the same as it would be in a much larger breach.
What Was Exposed in the noreply_google_com Leak
- Email addresses
- Plaintext passwords
- URLs tied to each credential pair
Why This Matters
A working email and password pair is enough for an attacker to attempt credential stuffing against other accounts owned by the same person, including email, banking, and shopping logins. If the password is reused, a single entry from this small file can lead to account takeover or financial fraud.
How a Combolist Like This Comes Together
Even small combolists like this one are usually built from credentials pulled out of larger stealer log infections or older leaks, then filtered down and shared as a smaller, more targeted file, in this case one associated with Google related addresses.
Check If You Are Affected
Use HEROIC's free breach scanner to check your email against more than 400 billion leaked records, including this noreply_google_com file, and confirm whether your password needs to change.
Breach Breakdown
40 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds